2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-26237MEDIUM5.5The default privileges for the running service Normand Viewer Service in Beckman Coulter Remisol Advance v2.0.12.1 and p...
CVE-2022-22503MEDIUM6.1IBM Robotic Process Automation 21.0.0 could allow a remote attacker to hijack the clicking action of the victim. By pers...
CVE-2022-42247MEDIUM6.1pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This v...
CVE-2022-42306MEDIUM5.5An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can...
CVE-2022-42300MEDIUM6.5An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server...
CVE-2022-41427MEDIUM6.5Bento4 v1.6.0-639 was discovered to contain a memory leak in the AP4_AvcFrameParser::Feed function in mp4mux.
CVE-2022-41426MEDIUM6.5Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_AtomFactory::CreateAtomFromStream function in mp4s...
CVE-2022-41425MEDIUM6.5Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in...
CVE-2022-41424MEDIUM6.5Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_SttsAtom::Create function in mp42hls.
CVE-2022-41423MEDIUM6.5Bento4 v1.6.0-639 was discovered to contain a segmentation violation in the mp4fragment component.
CVE-2022-41420MEDIUM5.5nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component
CVE-2022-41419MEDIUM6.5Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt bina...
CVE-2022-3132MEDIUM4.8The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2022-3128MEDIUM4.8The Donation Thermometer WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could al...
CVE-2022-3124MEDIUM5.3The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files f...
CVE-2022-2839MEDIUM5.4The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJA...
CVE-2022-2763MEDIUM4.8The WP Socializer WordPress plugin before 7.3 does not sanitise and escape some of its Icons settings, which could allow...
CVE-2022-2628MEDIUM4.8The DSGVO All in one for WP WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could a...
CVE-2022-40922MEDIUM6.5A vulnerability in the LIEF::MachO::BinaryParser::init_and_parse function of LIEF v0.12.1 allows attackers to cause a de...
CVE-2022-40123MEDIUM6.5mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor...
CVE-2022-32173MEDIUM5.4In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security rol...
CVE-2022-36551MEDIUM6.5A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5....
CVE-2022-40923MEDIUM6.5A vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a...
CVE-2022-35155MEDIUM6.1Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the s...
CVE-2022-20945MEDIUM6.5A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Points (APs) could allow...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now